1. Scope and roles
This DPA supplements the Trelyqo Terms or other agreement between Keephy and Customer. It applies only to the extent Keephy processes personal data on behalf of Customer as processor. Customer is controller or processor, as applicable, and Keephy is Customer’s processor/subprocessor for the relevant Customer Personal Data.
2. Documented instructions
Keephy will process Customer Personal Data only on documented instructions from Customer, including instructions inherent in use of the Services and this DPA, unless law requires otherwise. If legally permitted, Keephy will notify Customer of a legally required processing instruction that conflicts with Customer instructions.
3. Confidentiality
Keephy will ensure persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
4. Security measures
Keephy will implement technical and organisational measures appropriate to risk, taking account of the state of the art, implementation costs, processing context and risks to individuals. Measures may include access control, authentication, least privilege, encryption in transit where appropriate, logging, backup, vulnerability management, incident response and provider due diligence. See Security.
5. Subprocessors
Customer grants general authorisation for Keephy to use subprocessors to provide the Services. Keephy will maintain a list at Subprocessors and impose data-protection obligations on subprocessors appropriate to the processing. Where law requires an objection mechanism for a new subprocessor, Keephy will provide reasonable notice and an opportunity to object on legitimate data-protection grounds.
6. Data-subject rights and compliance assistance
Taking account of the nature of processing, Keephy will provide reasonable assistance to Customer with legally required responses to data-subject requests, DPIAs and regulatory consultations, to the extent the relevant information is available to Keephy and Customer cannot reasonably fulfil the obligation without assistance.
7. Personal-data breaches
Keephy will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data, and will provide information reasonably available to support Customer’s legal obligations. Notification is not an admission of fault or liability.
8. Restricted transfers
Where a transfer of Customer Personal Data is restricted by UK or EEA data-protection law, the parties will use an appropriate lawful transfer mechanism, which may include adequacy, the UK IDTA, the UK Addendum to EU SCCs, EU SCCs where applicable, or another valid mechanism. Keephy may implement reasonable supplementary measures appropriate to risk.
9. Return and deletion
At the end of Services, Keephy will delete or return Customer Personal Data in accordance with the agreement and Customer instructions, subject to backups, legal retention requirements and technical limitations. Data retained solely in backups will remain protected and be deleted through ordinary backup cycles.
10. Information and audits
Keephy will make information reasonably necessary to demonstrate compliance with processor obligations available to Customer. Audits must be reasonable, proportionate, subject to confidentiality, avoid unnecessary disruption and generally rely first on available independent reports, certifications, security documentation and questionnaires. On-site audits may be subject to advance notice, security restrictions and reasonable costs unless law requires otherwise.
11. Schedule — details of processing
| Subject matter | Provision, operation, support, security and maintenance of Trelyqo. |
|---|---|
| Duration | For the service relationship plus limited retention/backup periods required by contract or law. |
| Nature and purpose | Hosting, storage, organisation, retrieval, display, transmission, logging, support, security and deletion of Customer Personal Data. |
| Data subjects | Customer employees, contractors, authorised users, release participants and other individuals whose data Customer submits. |
| Data categories | Identity/contact, role/team, release assignment, availability/absence, cover, workspace activity, audit data and other Customer-submitted business data. |
| Sensitive data | Not intended unless expressly agreed and supported. Customer should avoid special-category and highly sensitive data. |
12. Liability and precedence
The liability limits and exclusions in the governing agreement apply to this DPA to the fullest extent permitted by law, unless a signed agreement expressly provides otherwise. If this DPA conflicts with the agreement on personal-data processing obligations, this DPA prevails for that conflict.